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Listing of the Claims 



1 . (currently amended) In a computer system, a method comprising: 



receiving information 
detennining whether 



verifying performed by a verification mechanism, and if not valid, preventing the 



possible change from being 



information indicative of the 



component. 

2. (original) The 
indicative of a possible char|ge 
to a protected file. 



3. (original) The 
indicative of a possible 
and accessing information 



4. (original) The 
includes overwriting a 
file. 



5. (canceled) 



indicative of a possible change to a protected file; and 
the possible change is valid by verifying the file, the 



implemented including discarding chang e data the 



possible change and retuming a success to a 



method of claim 1 wherein receiving information 

includes receiving notification indicative of a change 



method of claim 1 wherein receiving information 
char^ge includes receiving notification of a change to a file. 
tt> determine whether the file is protected. 



method of claim 1 wherein preventing the change 
changed copy of the file with a valid copy of the protected 
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6. (currently amended) The method of claim 1 wherein determining 
whether the possible change is valid by verifying the file includes obtaining 
cryptographic hash information of the changed file and comparing the 
cryptographic hash informa1,ion against cryptographic hash infonrtation associated 
with the protected file. 



7. (original) The 
cryptographic hash information 
protected files. 



8. (currently 
whether the possible chang^ 
a signature. 



amended) The method of claim 1 wherein determining 

is valid includes determining whether the file includes 



9. (original) The 
in a file system. 



10. (currently amended) 
possible change includes c<[»pying 
location of the protected file 



11. (original) The 
protected file includes findinig 



method of claim 6 wherein comparing the 

includes accessing a catalog of information for 



method of claim 1 further comprising, monitoring files 



The method of claim 1 wherein preventing the 
a valid copy of the protected file to a former 



method of claim 10 wherein copying a valid copy of the 
a file having the same identity as the protected file. 
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12. (original) The 
same identity as the protected 



13. (original) The 
having the same identity. 



14. (original) The 
same identity as the 



method of claim 1 1 wherein finding the file having the 
protected file includes accessing a network. 



15. (original) The 
having the same identity. 



16. (original) The 
same Identity as the 



17. (original) The 
having the same identity. 

18. (canceled) 



19. (cunrently 
receiving information indica 



al. 



method of claim 1 1 wherein finding the file having the 
file includes accessing a cache- 



method of claim 12 further comprising verifying the file 



method of claim 14 further comprising verifying the file 



method of claim 15 wherein finding the file having the 
protectbd file includes accessing a recorded medium. 



method of claim 16 further comprising verifying the file 



amended) The method of claim 1 further comprising 
ing that a protected file is about to be changed. 
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preserving a copy of the protected 
includes overwriting a changed 
was preserved. 



(4251 03G-8957 



comprising: 



lity 



20. (currently 
executable instructions, 

(1) selecting a plura 

(2) receiving information 

(3) determining whether 

(a) if an exceFjti 

(b) if not an 
is valid by verifying the file, 
and 

(i) if 

and 

(ii) if no 

implemented : and 

(4) returning i 



amended) A computer-readable medium-having computer- 



21. (original) The 
receiving information indica 
indicative of a change to a 



p. 9 



file, and wherein preventing the possible change 
copy of the file with a copy of the protected file that 



of files as protected files; 
ion indicative of a possible change to a protected file; 

the file is an exception case, and 
ion case, allowing the change, or 
e)fception case, determining whether the possible change 
[he verifying performed by a verification mechanism, 

valid, allowing the possible change to be implemented : 

t valid, preventing the possible change from being 

nformal ion indicative of a success. 



computer-readable medium of claim 20 wherein 
ive of a possible change includes receiving notification 
brotected file. 
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22, (original) The 
receiving infomnation indicat 
of a change to a file, and 
protected - 



computer-readable medium of claim 20 wherein 
ve of a possible change includes receiving notification 
accessing information to determine whether the file is 



23. {cun-ently 
wherein preventing the 



ame|nded) The computer-readable medium of claim 20 
possjible change includes overwritirKj a changed copy of the 



file with a valid copy of the protected file. 



24. (currently 
wherein preventing the 



amejnded) The computer-readable medium of claim 20 
possible change includes discarding change data. 



25, (canceled) 



26. (currently ameinded) The computer-readable medium of claim 20 
wherein allowing the possib e change includes writing data saved via a copy-on- 
write process to the file. 

27. (original) The computer-readable medium of claim 20 wherein 
determining whether the file is an exception case includes checking a security 
descriptor of the file. 
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28- (currently 
further comprising providing 



amerSded) The computer-readable medium of claim 20 
a prompt before allowing a possible change. 



29. {currently 
wherein detemaining whethe 
cryptographic hash 
cryptographic hash 
with the protected file 



ameihded) The computer-readable medium of daim 20 
r the possible change is valid includes obtaining 
information of the changed file, and comparing the 
informatjon against cryptographic hash information associated 



30. (currently ame 
wherein determining whether 
whether the file includes a s 



servi ::e 



a verification mechar) 
a file protection 
determination from the 
changed, and further confij 
verify whether the possible 



ided) The computer-readable medium of daim 20 
the possible change is valid includes determining 
gnature. 



31. (currently amejnded) A computer system, comprising, 
a protected file, 

a detection mechanism configured to detemnine when the protected file may 
be changed bv a possible chang e. 



ism; and 

, the file protection service configured to receive a 
deteiction mechanism that the protected file may be 
nfigured to communicate with the verification mechanism to 
change is valid, and to prevent the possible change 
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from being implemented by discarding 
possible change is not valic . 



*ta the possible change when the 



32. (original) The 
mechanism includes a mechanism 
to at least one file therein. 



33. (original) The 
mechanism provides a notification 
mechanism that the protect^ 



34. (original) The 
service accesses a data structure 
from the detection mechanii»m 



35. (original) The 
service is incorporated into 

36. (canceled) 



37. (previously presented) 
file protection service return 



computer system of claim 31 wherein the detection 

for monitoring at least one directory for changes 



computer system of claim 31 wherein the detection 

to the file protection service as the determination 
file may be changed. 



computer system of claim 31 wherein the file protection 
to determine whether the notification received 
corresponds to a protected file. 



computer system of claim 31 wherein the file protection 
file system. 



The computer system of claim 31 wherein the 
s information indicative of a success. 
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38. (currently 
verification mechanism 
comparing a cryptographic 
associated with a valid file. 



amended) The computer system of claim 31 wherein the 
veriffes whether the possible change to a file is valid by 
hash of the file contents against a cryptographic hash 



39. (original) The 
cryptographic hash associatlBd 
including a cryptographic halsh 



computer system of claim 38 wherein the 

with a valid file is maintained in a data structure 
of the contents of at least one other protected file. 



40-45, (canceled) 

46. (currently amejnded) A computer system, comprising, 
a protected file, 

a detection mechanism configured to determine when the protected file may 
be changed by a possible change : 



changed, and further config 
verify whether the possible 



a verification mechanism; and 

a file protection service, the file protection service configured to receive a 
determination from the detection mechanism that the protected file may be 

I jred to communicate with the verification mechanism to 
change is valid, and to prevent the possible change 
from beino implemented by locating valid data in a system cache and copying the 
valid data over changed dai a when the possible change is not valid. 
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nded) A cx)mputer system, comprising, 



47. (currently amer 
a protected file, 

a detection mechanism configured to determine when the protected file may 
be changed by a possible change : 



service 



a verification 
a file protection 
detemiination from the 
changed, and further con 
verify whether the possible 
from being implemented by 
valid data over changed dat 



mechanism; and 

, the file protection service configured to receive a 
detection mechanism that the protected file may be 
figured to communicate with the verification mechanism to 
^hange is valid, and to prevent the possible change 
ocating valid data at a network share arKi copying the 
a when the possible change is not valid. 



48. (currently amejnded) A computer system, comprising, 
a protected file, 

a detection mechanism configured to detemnine vfhen the protected file may 
be changed by a possible change : 



verify whether the possible 



from being implemented by 
the valid data over changed 



a verification mechar ism; and 

a file protection servi ::e, the file protection service configured to receive a 
determination from the dete::tion mechanism that the protected file may be 
changed, and further config jred to communicate with the verification mechanism to 

ohange is valid, and to prevent the possible change 
locating valid data In a recorded medium and copying 
data when the possible change is not valid. 
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49. (previously presented) The computer system of claim 46 further 
comprising a scanning mecJanism for causing a plurality of files to trigger the 
detection mechanism. 
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